Penetration Testing

Professional penetration testing for UK businesses

Identify exploitable vulnerabilities before attackers do.

Independent, manual penetration testing of web applications, APIs, networks and external infrastructure, delivered by experienced security professionals.

Qualified testers Clear, actionable reporting No-obligation consultation
What a finding actually looks like

Not a scanner printout. A story you can act on.

Every finding explains what we found, how we proved it, and exactly what to fix, so your engineers aren't left guessing at what a CVE number means for them.

Manual testing

Don't just scan it. Test it.

Automated vulnerability scanners are useful, but they don't replace a skilled penetration tester.

Our penetration tests combine industry-standard tooling with manual security testing to identify vulnerabilities that automated scanning can miss, including authentication weaknesses, access control issues, business logic flaws and privilege escalation.

The objective isn't simply to produce a list of vulnerabilities. It's to establish what an attacker could actually achieve.

Automated scanner

Good at breadth

Fast, consistent, and useful for catching known CVEs and missing patches at scale.

  • Known vulnerabilities and outdated software
  • Missing security headers and misconfigurations
  • A long list, with no sense of what actually matters
Manual test

Good at judgement

A human working out what a scanner can't: whether an issue is exploitable, and what happens if it is.

  • Business-logic and authorisation flaws
  • Chained issues that add up to real impact
  • A prioritised list of what to fix first, and why
Scope

What can we test?

Web applications

Web application penetration testing

Test your web application for vulnerabilities including:

  • Authentication and session management
  • Access control and IDOR
  • Injection vulnerabilities
  • Cross-site scripting
  • File upload vulnerabilities
  • Business logic flaws
  • Privilege escalation
  • Security misconfigurations
Web application penetration testing
APIs

API penetration testing

Test the APIs that expose your applications and data:

  • Authentication and authorisation
  • Object-level authorisation
  • IDOR and BOLA
  • Injection
  • Rate limiting
  • Data exposure
  • Business logic
  • API-specific OWASP risks
API penetration testing
External infrastructure

External penetration testing

Assess your internet-facing infrastructure from an attacker's perspective:

  • Public-facing services
  • Firewalls
  • VPNs and remote access
  • Web services
  • Network services
  • TLS/SSL configuration
  • Exploitable vulnerabilities
External penetration testing
Internal networks

Internal penetration testing

Understand what could happen if an attacker gains access to your internal environment:

  • Active Directory
  • Privilege escalation
  • Lateral movement
  • Credential exposure
  • Network segmentation
  • Misconfigurations
  • Excessive privileges
Internal penetration testing
Timing

When should you conduct a penetration test?

Not sure whether now is the right time? These are the moments that most often call for a test.

  • Before launching a new application
  • After significant changes to an application or infrastructure
  • Before a major procurement or customer security review
  • Following significant security remediation
  • As part of a compliance programme
  • Periodically as part of your security assurance programme
Methodology

What does a penetration test include?

A structured engagement from scoping through to retesting, so nothing is left to chance.

  1. Scope

    We establish what needs testing and agree the rules of engagement.

  2. Reconnaissance

    We identify the attack surface and understand the target.

  3. Manual testing

    Our testers investigate vulnerabilities and attempt controlled exploitation.

  4. Validation

    Findings are validated to minimise false positives and establish real-world impact.

  5. Reporting

    You receive a detailed technical report and an executive-level summary.

  6. Remediation

    We can discuss findings with your team and recommend appropriate remediation.

  7. Retesting

    Once remediation is complete, we can verify that vulnerabilities have been addressed.

Deliverables

What will you receive?

A report your board and your engineers can both act on.

Executive summary

The headline for decision-makers

A concise, plain-English overview your board and stakeholders can act on without reading the technical detail:

  • Overall security posture and risk rating
  • The key risks and what they mean for the business
  • A breakdown of findings by severity
  • The most significant issues at a glance
  • Recommended priorities for remediation
Technical findings

Everything your engineers need

For each vulnerability:

  • Description
  • Severity
  • Affected asset
  • Evidence
  • Impact
  • Reproduction details
  • Remediation recommendation
Risk prioritisation

What to fix first

Findings prioritised according to their potential impact and exploitability.

Remediation guidance

Clear, actionable next steps

Recommendations your technical team can act upon, plus optional retesting to verify remediation.

Why Plainsight

What makes Plainsight Security different?

Manual testing by experienced testers

We don't simply run a vulnerability scanner and send you the results.

Business-focused reporting

We explain the vulnerability, its impact, evidence of exploitation and how to remediate it.

Real-world attack methodology

Testing is performed from the perspective of an attacker, using recognised industry methodologies.

Clear communication

No unnecessary jargon. You'll understand what we've found and what needs to be done.

Remediation support

Have questions about a finding? We can discuss the issue with your technical team and help you understand the appropriate remediation.

Who it's for

Who needs penetration testing?

SaaS & technology companies

Demonstrate that your application and infrastructure have been independently security tested.

Professional services

Support customer security requirements and procurement questionnaires.

Financial & regulated organisations

Obtain independent assurance of your security controls.

Suppliers to larger organisations

Meet customer and supplier assurance requirements.

Organisations preparing for compliance

Support wider security and compliance programmes.

Businesses launching new applications

Identify vulnerabilities before your application reaches customers.

Point-in-time

Penetration testing isn't a one-off tick box

A penetration test provides a point-in-time assessment of your security. As applications, infrastructure and threats evolve, your attack surface changes too.

We recommend reassessing systems periodically and following significant changes, to ensure previous security assumptions remain valid.

Need another test later?

We'll be here when your requirements change

We'd be happy to work with you as your security testing requirements evolve. No retainer, no pressure, just testing when it makes sense for you.

Talk to us about scope
Case study

Recent penetration test, in the client's own words

A look at how a recent engagement went, from scope to final report.

All case studies
FaiceTech Ltd logo Web Application Penetration Test

“Plainsight are clearly experienced and dug into our system in ways we never envisaged - I'm delighted with the output and learning.”

Chris Noden, FaiceTech

Read the FaiceTech Ltd case study
Credentials

Independent. Experienced. Security-focused.

  • UK Cyber Security Council registered Principal (PriCSP) in Security Testing
  • Infrastructure testing by a Cyber Scheme Team Leader qualified tester
  • Web application and API testing to OWASP-aligned methodology
  • UK-based security consultancy
  • Manual penetration testing, not just automated scanning
  • Clear, actionable reporting
Common questions

Penetration testing, answered.

How much does a penetration test cost?

There's no fixed public price, because it depends on scope: whether you need external, internal, web application or API testing, how many hosts or endpoints are in play, and whether authentication is involved. Tell us what you're looking to test on a short scoping call and we'll come back with a fixed-price quote, typically within 48 hours.

Who actually carries out the testing?

An experienced, senior tester runs your engagement from scoping to report, with no hand-off to a junior halfway through. Infrastructure testing is delivered to a recognised methodology by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and our lead tester is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing. Web application and API testing follows the OWASP-aligned methodology.

What's the difference between a penetration test and Cyber Essentials Plus?

Cyber Essentials Plus is a hands-on audit of the five Cyber Essentials controls, sampled across your devices and users. A penetration test goes much further: it actively tries to break into the scope you define, whether that's your external perimeter, internal network, or web applications and APIs, and chains issues together the way a real attacker would. Many organisations hold both, because they answer different questions.

What's the difference between a penetration test and an automated vulnerability scan?

A scanner is fast and useful for catching known CVEs and missing patches at scale, but it can't tell you whether an issue is actually exploitable or what an attacker could do with it. A penetration test combines that tooling with manual testing: a skilled tester investigates business logic, authorisation flaws and chained issues that a scanner simply doesn't understand, and validates findings to rule out false positives.

Can you test web applications, APIs and infrastructure together?

Yes. External, internal and web application testing answer different questions, and many engagements combine two or three of them for a fuller picture of your attack surface. Tell us your environment on a scoping call and we'll recommend the right combination, not the biggest one, then provide a single fixed-price quote covering everything in scope.

How long does a penetration test take, and will it disrupt us?

Most tests run over a few days, depending on scope, and can be scheduled out of hours to suit your team. We agree the rules of engagement in writing before testing starts and stay in contact throughout, so there are no surprises and minimal disruption to your normal operations.

Do you retest once we've fixed the issues?

Yes. Once you've remediated the findings, we retest to confirm the fixes hold, at no extra cost. It's included as standard, not sold as an add-on.

How often should we have a penetration test?

There's no single answer, but the moments that most often call for one are before launching a new application, after significant changes to your infrastructure, ahead of a major procurement or customer security review, and periodically as part of an ongoing security assurance programme. A penetration test is a point-in-time assessment, so we'd recommend reassessing as your environment changes rather than treating it as a one-off.

Get a quote

Find out what your penetration test would cost

Tell us what you're looking to test and we'll recommend an appropriate scope and provide a no-obligation quotation.

  1. We read your enquiry

    A real tester, not a sales team, so the first reply is already useful.

  2. A short scoping call

    15 to 30 minutes to understand your environment and what you need to prove.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

Not sure what type of test you need? That's fine. Tell us what you're trying to achieve and we'll help you determine the appropriate scope.